Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2014-9970
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2014-9970
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-9970.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2014-9970
Aliases
GHSA-r5c2-rxh2-f5h2
Downstream
DEBIAN-CVE-2014-9970
RHSA-2017:2808
RHSA-2017:2809
RHSA-2017:2811
RHSA-2017:2904
RHSA-2017:2905
RHSA-2017:3141
UBUNTU-CVE-2014-9970
Published
2017-05-21T18:29:00Z
Modified
2025-08-09T19:01:27Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
[none]
Details
jasypt before 1.9.2 allows a timing attack against the password hash comparison.
References
https://access.redhat.com/errata/RHSA-2017:2546
https://access.redhat.com/errata/RHSA-2017:2547
https://access.redhat.com/errata/RHSA-2017:2808
https://access.redhat.com/errata/RHSA-2017:2809
https://access.redhat.com/errata/RHSA-2017:2810
https://access.redhat.com/errata/RHSA-2017:2811
https://access.redhat.com/errata/RHSA-2017:3141
https://access.redhat.com/errata/RHSA-2018:0294
https://sourceforge.net/p/jasypt/code/668/
http://www.securitytracker.com/id/1039744
http://www.securitytracker.com/id/1040360
Affected packages
CVE-2014-9970 - OSV